Auditor impartiality and conflict of interest checks in scheduling
How to spot an auditor conflict of interest before it reaches the audit plan: ISO/IEC 17021-1 threats, the two-year rule, declarations and allocation checks.
Key takeaways
- ISO/IEC 17021-1 names four threats to impartiality: self-interest, self-review, familiarity and intimidation.
- Personnel who provided management system consultancy to a client must not take part in its audits within two years of the consultancy ending.
- Declarations only protect you if they are structured, dated and checked automatically at allocation.
- Clients are told the team in advance and can object, which is a second check but never the first.
An auditor conflict of interest is any relationship that could compromise, or appear to compromise, an auditor's impartiality towards a client, such as recent consultancy, employment, family ties or financial interest. ISO/IEC 17021-1 requires personnel to reveal such situations, bars people who gave management system consultancy to a client from its audits for two years, and expects the body to check before allocation.
What counts as an auditor conflict of interest?
An auditor conflict of interest is any situation in which an auditor's own interests or relationships could affect, or be seen to affect, their judgement about a client. Clause 4.2 of ISO/IEC 17021-1:2015 frames this as four threats to impartiality. Being impartial and being perceived as impartial both matter.
For planners, the question is concrete: does anything connect this person to this client that would make an assessor, the client's competitor or the public doubt the result?
Self-interest
Acting in one's own interest, including financial interest, for example shares in the client or a bonus tied to the outcome.
Self-review
Reviewing one's own work, such as auditing a management system the auditor helped design as a consultant.
Familiarity
Being too familiar with or trusting of the client instead of seeking evidence. Long relationships and auditor rotation rules sit here.
Intimidation
Feeling coerced, openly or secretly, for example by a threat to be replaced or reported to a supervisor.
What does ISO/IEC 17021-1 require on impartiality?
- A process to identify, analyse, evaluate, treat, monitor and document risks arising from conflicts of interest, including those from personnel, contracts, training and shared resources.
- The body itself must not offer management system consultancy or internal audits to its certified clients.
- Where a client received consultancy from a body that has a relationship with the certification body, a recognised mitigation is not to certify the management system for a minimum of two years after the consultancy ends (clause 5.2.7).
- Personnel who provided management system consultancy to a client must not take part in its audits or certification activities within two years following the end of the consultancy.
- All personnel, internal and external, must reveal any situation known to them that could present a conflict of interest.
- External auditors and technical experts work under a written agreement committing them to the body's policies, including impartiality (clause 7.3).
- The client receives the name of each audit team member in time to object to any of them.
A European Accreditation FAQ (question 33.1, March 2017) adds that an individual running their own consultancy company counts as a 'body' for clause 5.2.7. That matters for freelance auditors who also consult; see managing subcontracted auditors.
How does the two-year rule work in practice?
Take a contract auditor who helped a manufacturer implement ISO 14001, with the engagement ending on 31 March 2025. They cannot take part in that client's audits or certification activities before 31 March 2027. If the planner only records 'has consulted for client X' without the end date, the rule cannot be checked; if the end date is recorded, the check is mechanical.
Where do auditor conflict of interest checks fit in scheduling?
Conflict checks work best as a flow that starts long before the audit and ends with a record.
- 1DeclareAuditor lists clients, employers, consultancy, dates
- 2StructureStore each link against the client record
- 3CheckFilter conflicted auditors before allocation
- 4Notify clientSend team names in time to object
- 5RecordLog the check and any decision
The client's right to object is a useful second line, but it is not a control you can rely on: clients rarely know an auditor's history, and a late objection costs you the date.
What should every conflict declaration capture?
Ask for declarations at onboarding, at least yearly and whenever circumstances change. Each entry needs enough detail for a machine to check it.
- ✓Client or group name, with the specific sites where relevant
- ✓Nature of the link: consultancy, employment, training, family, financial or other
- ✓Start and end dates of the relationship
- ✓Whether it involved the management system being certified
- ✓Links through a consultancy the auditor owns or works for
- ✓Date of the declaration and the auditor's confirmation it is complete
- ✓The body's decision: excluded from client, excluded until a date or no conflict
Myths about auditor impartiality
MythThe two-year rule only applies to our own staff.
RealityIt applies to personnel, and ISO/IEC 17021-1 extends impartiality obligations to external auditors through written agreements.
MythTraining a client's staff is always consultancy.
RealityPublic or generic training is usually treated differently from client-specific advice. Record it and let your impartiality process decide.
MythIf the client doesn't object, the team is fine.
RealityClients cannot see an auditor's past. The body must check first.
MythA declaration signed once covers the future.
RealityCircumstances change. Refresh declarations regularly and when an auditor takes on new work.
Common scheduling mistakes with impartiality
Group structures cause the most misses. An auditor who consulted for one subsidiary may be conflicted for the whole group if the management system is shared. Record conflicts against the legal entity and the group, and let your impartiality process decide how far each one reaches. Then apply the same rule to every site in the programme, including sampled sites under a multi-site certificate.
- Holding declarations in HR files that planners never see.
- Recording conflicts against a client name that doesn't match the certificate holder or group structure.
- Checking the lead auditor but not co-auditors, technical experts or trainees.
- Swapping an auditor late, after a cancellation, without re-running the checks. See handling last-minute changes.
- Forgetting that the certification decision-maker also needs to be free of conflicts.
ScheduleAI stores conflicts of interest as dated exclusions against clients and groups and checks them for every team member on every proposal, including late swaps. An audit trail for scheduling decisions then shows an assessor that the check ran.
ScheduleAI is audit scheduling software built for testing, inspection and certification (TIC) organisations, with a planner approving every plan.
ScheduleAI treats conflicts of interest as dated rules against clients and groups, checks every team member on every proposed allocation and records the result for planners and assessors.
Book a demo Estimate your savingsQuestions
What is an auditor conflict of interest?
Any relationship or interest that could compromise, or appear to compromise, an auditor's impartiality towards a client, such as recent consultancy, employment, family ties or financial interest.
What is the two-year rule in ISO/IEC 17021-1?
Personnel who provided management system consultancy to a client must not take part in its audits or certification activities within two years of that consultancy ending.
Does the two-year rule apply to freelance auditors?
Yes. It applies to personnel, and a European Accreditation FAQ treats an individual with their own consultancy company as a body for clause 5.2.7.
How often should auditors declare conflicts?
ISO/IEC 17021-1 requires personnel to reveal known conflicts; most bodies collect declarations at onboarding, yearly and whenever circumstances change.
Do technical experts need conflict checks?
Yes. Clients are told every team member in advance, and the body must manage impartiality risks from all personnel, internal and external, including technical experts.
Can the client veto an auditor?
The client is told the team in advance and can object; the body then reconsiders the team. See avoiding scheduling conflicts.